Indicator of Compromise Search
Bulk Lookup
✦ IPv4 Address ✦ Domain ✦ MD5/SHA1/SHA256 Hash ✦ URL
INDICATOR
norderswing.buzz
Domain ⚠ 3 PULSE HITS
↓ CSV ↓ JSON
30
/100
MEDIUM
CONFIDENCE LEVEL
THREAT CONFIDENCE ANALYSIS
MEDIUM 30/100 confidence
Some evidence of suspicious activity. Further investigation recommended before action.
CLEAN LOW MED HIGH CRIT
0 25 50 75 100
OTX
20/30
3 pulses
VIRUSTOTAL
/35
N/A
ABUSEIPDB
/25
IPv4 only
URLHAUS
10/10
LISTED
General Information
Indicatornorderswing.buzz
Whois Domainhttp://whois.domaintools.com/norderswing.buzz
Typedomain
AlienVault OTX Analysis ↗ View on OTX
3
PULSE HITS
Pulse Hits 3
Indicator Type Domain
Threat Level
ASSOCIATED PULSES
PULSE NAMEDATE
Expanded: Close proximity RMS module attack. Critical infrastructure affected. Medical, Business, Legal., Religious institutions 2025-05-20
iOS Critical PegasusLoader.exe on updated iOS devices 2025-05-20
URLHaus data - 01-03-2025 2025-03-02
VirusTotal Analysis ↗ View on VirusTotal
⚠ VirusTotal rate limit reached. Try again shortly.
URLhaus (abuse.ch) ↗ View on URLhaus
⚠ LISTED
URLHAUS
URLs Found 2
ASSOCIATED URLs
URL STATUS / TYPE DATE
https://norderswing.buzz/xp/ntdlg_s.zip offline 2025-03-01
https://norderswing.buzz/xp/system_s.js offline 2025-03-01